The Manchester Airport Group data breach, confirmed on 27 August 2026, has exposed the personal details of an estimated 8.7 million customers, with email addresses, phone numbers, vehicle registrations and postcodes taken by an unauthorised third party. Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, said it became aware of the incident on Tuesday and moved immediately to contain the breach.

The group said the compromised system did not hold bank or payment details. ‘We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems,’ MAG said in a statement. The hackers have been identified and relevant authorities informed. Airport operations, the company added, remain ‘unaffected’.

What was taken and who is affected

Customers notified by MAG were told their email addresses, phone numbers, vehicle registrations and postcodes had been accessed. The company was explicit that no banking or payment information was held on the system that was breached.

MAG wrote to affected customers urging caution: ‘We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us. We will never contact you unexpectedly to ask for payment or banking information. We apologise for any inconvenience or concern this may cause.’

Around 8.7 million people are believed to be affected across MAG’s three airports. To put that scale in context, Tech Insider reports that MAG’s combined passenger volume across all three airports totalled 61.3 million in its financial year 2024, with Manchester Airport alone recording 29.76 million passengers that year, its busiest calendar year on record. The breach figure of 8.7 million therefore represents a substantial portion of the group’s registered customer base built up across years of travel.

Manchester Airport Group data breach: the wider cost of cyber attacks on UK business

The incident arrives at a moment when the financial consequences of cyber attacks on large UK businesses are drawing renewed scrutiny. Research from insurance giant Gallagher and the Centre for Economics and Business Research (CEBR) found that cyber attacks cost firms with more than 250 employees an estimated £11.7 billion in total, with direct losses from disrupted trading accounting for the largest share at £5.4 billion.

Litigation was the second largest expense. Large UK businesses were forced to spend £3.7 billion defending legal action brought by shareholders over cyber attacks. Lost assets added a further £1.3 billion, while regulatory fines cost £108 million. Reputational damage generated £573 million in costs, and companies lost nearly £400 million in revenue from customers cancelling contracts, reducing spending or switching to alternative suppliers following attacks.

Those figures underline why MAG’s response speed matters. The group says it moved to prevent further access as soon as it became aware of the incident, though the two-day gap between the breach being discovered and the public announcement on Thursday will draw questions about notification timelines, particularly given the volume of personal data involved.

The Manchester Airport Group data breach follows a broader pattern of attackers targeting organisations that hold large volumes of consumer contact data. Vehicle registrations and postcodes, while less immediately exploitable than financial credentials, are frequently combined with email addresses and phone numbers to make phishing and vishing attempts more convincing. MAG’s warning to customers to treat unexpected contact with caution reflects that risk directly.

The group said specialist advisors are continuing to work with it on protective measures. With 61.3 million passenger journeys recorded across its three airports in the last financial year, the volume of customer data MAG holds across loyalty schemes, booking systems and operational databases makes it a target of considerable scale. Whether the incident triggers regulatory scrutiny under the UK’s data protection framework will become clearer as the relevant authorities review the information MAG has submitted.

Rhiannon Gethin spent a decade in public health before she picked up a byline. She trained in epidemiology at a Russell Group university, worked in health policy at a regional NHS trust, and did a stint at a public health consultancy advising local authorities on service commissioning. She left the policy side because she got tired of writing reports that sat in inboxes. She covers NHS funding, social care, preventative health, and the gap between what the evidence says and what actually gets implemented. She has read more NICE guidelines than any reasonable person should and retains an unhealthy interest in health inequalities data. Rhiannon lives in Cardiff and works remotely. She does not believe in superfoods, and treats most wellness content as advertising with a pulse oximeter attached.